An exploit chain designated ToolShell, combining CVE-2025-53770 and CVE-2025-53771, was used against internet-facing on-premises Microsoft SharePoint servers to achieve remote code execution and steal cryptographic material. The chain was identified on 18 July 2025 and confirmed under active exploitation on 19 July. Reporting places around 150 organisations among those reached.
Microsoft attributed activity to China-aligned intrusion sets it tracks as Linen Typhoon and Violet Typhoon, and to a third cluster designated Storm-2603 which deployed ransomware.
On-Premises, Which Is The Whole Point
The hosted version of the product was not affected in the same way. The organisations compromised were those running the software themselves — frequently for the reasons that most often justify it: regulatory requirements, data residency, integration with systems that cannot move, or a judgement that self-hosting is more secure.
What self-hosting actually transfers is the patch obligation. A hosted service is remediated by the vendor across every tenant simultaneously; an on-premises estate is remediated by whoever is available, at whatever pace their change process permits. In a window measured in days, that difference decides the outcome.
This desk does not read that as an argument for hosted services generally — the concentration files throughout this corpus record what happens when everyone depends on one provider. It is an argument that the trade has two sides and only one of them is usually counted.
Three Actors, One Chain, Different Objectives
Two of the named clusters are assessed as espionage operations. The third deployed ransomware. The same exploit chain served collection and extortion within days of each other.
That is worth recording because the corpus organises itself by actor motive — nation-state, ransomware, criminal — and this file demonstrates that the categories describe intent rather than capability. A working exploit is available to anyone who obtains it, and the defensive question is identical regardless of who arrives.
A Document Store Is A Document Store
SharePoint holds the material an organisation writes down: contracts, board papers, incident reports, personnel matters, engineering documentation. It is not a database of customer records and it does not generate a notification with an affected count.
For an espionage operation it is a better target than a customer database, and it is the category the breach registers do not capture — the same measurement gap filed at 25-1204 for manufacturing intellectual property.
Compiled from vendor advisories and public research, listed below. Attribution follows Microsoft’s published assessment as reported. The 150 figure is a reported count of identified victims and should be read as a floor. Corrections: corrections@forensicpost.com.